Summary
- Who we are: Archilas provides persistent memory infrastructure for AI agents. We are based in Greece.
- What we process: Account details, API usage metadata, and content you submit so we can distill structured memory. We do not store raw chat transcripts as part of our core memory model.
- Why we process it: To operate the Service, authenticate users, provide support, secure our platform, and comply with law.
- Model training: We do not use your memory content or API payloads to train foundation models for third parties. We do not sell personal information.
- Your rights: Depending on where you live, you may have rights to access, correct, delete, export, or restrict processing of your data.
- Contact: hello@archilas.com
1. Scope and roles
This Privacy Policy applies to personal information Archilas processes as a data controller when you visit archilas.com, create an account, join our waitlist, contact us, or use our hosted API at api.archilas.com and MCP endpoint at mcp.archilas.com.
If you use Archilas to store memory on behalf of your own end users (for example, customers of your AI product), you are typically the data controller for their personal information and Archilas acts as a processor. In that case, our processing is governed by your agreement with us and, where applicable, a Data Processing Addendum ("DPA"). If you are an end user of a product powered by Archilas, please contact that product's operator with privacy questions.
2. Data controller
For purposes of the EU General Data Protection Regulation ("GDPR") and UK GDPR, the data controller is Archilas. Privacy inquiries: hello@archilas.com.
3. Information we collect
3.1 Information you provide
- Account and waitlist information: name, email address, organization, authentication credentials, billing contact details, and communications you send us.
- Memory inputs: conversation content, prompts, messages, metadata, and identifiers (such as
user_id) that you submit through the API, MCP, or SDKs so we can distill and store structured memory entries.
- Support and sales communications: information in emails, forms, or meetings with our team.
- Payment information: paid plans are processed by third-party payment providers. We receive limited billing metadata (such as subscription status and transaction references), not full card numbers.
3.2 Information collected automatically
- Usage and device data: IP address, browser type, operating system, pages viewed, referring URLs, timestamps, API request metadata, error logs, and diagnostic events.
- Security data: authentication events, rate-limit signals, and abuse-prevention telemetry.
- Cookies and similar technologies: see Section 12.
3.3 Information from third parties
We may receive information from authentication providers (such as Google OAuth), payment processors, analytics providers, and publicly available sources where permitted by law.
4. How Archilas handles memory data
Archilas is designed to store structured memory, not raw conversation archives. Our Skeleton, Vault, and Distiller architecture processes submitted content to extract claims, commitments, signals, and related metadata with extraction confidence scores.
- We process submitted content only to provide memory storage, retrieval, distillation, auditing (where enabled), and related features you request.
- Transient processing may occur in memory or short-lived logs for reliability and security; we do not operate the Service as a long-term transcript repository.
- Enterprise and self-hosted deployments may keep data entirely within your environment, subject to your configuration and agreement with us.
5. How we use personal information
We use personal information to:
- Provide, maintain, secure, and improve the Service
- Create and administer accounts, waitlist access, and API keys
- Authenticate requests to api.archilas.com and mcp.archilas.com
- Process subscriptions and billing for Free, Pro, and Enterprise plans
- Respond to support requests and communicate service updates
- Monitor performance, debug incidents, and prevent fraud or abuse
- Comply with legal obligations and enforce our Terms of Service
- Send marketing communications where permitted, with opt-out available
6. Legal bases for processing (EEA/UK)
Where GDPR or UK GDPR applies, we rely on:
- Contract: to provide the Service and manage your account or waitlist access
- Legitimate interests: to secure, improve, and analyze the Service, prevent abuse, and communicate about similar services, balanced against your rights
- Consent: where required for non-essential cookies or certain marketing
- Legal obligation: to comply with applicable law, lawful requests, and regulatory requirements
7. AI and model training
We do not use Customer memory content, prompts, or API payloads to train generalized AI models for unrelated third-party products. We may use aggregated, de-identified usage statistics to improve reliability, latency, and product design. If we ever introduce optional features that involve model training on customer content, we will provide clear notice and appropriate controls or opt-outs before doing so.
8. How we share information
We do not sell personal information. We may share information with:
- Service providers: hosting, cloud infrastructure, email, analytics, customer support, and payment processors bound by confidentiality and data protection obligations
- Professional advisers: lawyers, accountants, insurers where reasonably necessary
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy
- Legal and safety: when required by law or to protect rights, safety, and security
- With your direction: when you integrate third-party tools or authorize disclosures
9. International transfers
We may process information in Greece and other countries where our providers operate. When we transfer personal information outside the EEA or UK, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms, unless an adequacy decision applies.
10. Data retention
We retain personal information only as long as necessary for the purposes described in this Policy, unless a longer period is required by law.
- Memory entries: retained until you delete them, delete the associated memory system, or close your account, subject to plan limits and backup cycles.
- Account data: retained while your account is active and for a reasonable period afterward for legal, billing, and security purposes.
- Logs: retained for limited operational and security periods, then deleted or aggregated.
- Enterprise retention policies: may be configured contractually, including legal hold and custom deletion schedules.
11. Security
We implement technical and organizational measures designed to protect personal information, including encryption in transit (TLS), access controls, API key authentication, monitoring, and least-privilege internal access. No method of transmission or storage is completely secure; you are responsible for safeguarding your API keys and account credentials.
12. Cookies and analytics
We use cookies and similar technologies to operate the website, remember preferences, measure traffic, and improve performance. Strictly necessary cookies support authentication and security. Where required by law, we obtain consent before placing non-essential cookies. You can manage cookies through your browser settings and, where available, our cookie preferences interface.
13. Your privacy rights
Depending on your location, you may have the right to:
- Access, correct, or delete personal information
- Export portable copies of your data
- Restrict or object to certain processing
- Withdraw consent where processing is consent-based
- Lodge a complaint with your local supervisory authority
To exercise these rights, email hello@archilas.com. We may need to verify your identity before responding.
California residents
We do not sell or share personal information for cross-context behavioral advertising as defined by the California Consumer Privacy Act, as amended. California residents may request access, deletion, or correction subject to applicable exceptions. We do not knowingly sell personal information of consumers under 16.
14. Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
15. Third-party services and links
The Service may link to third-party websites, model providers, or developer tools. Their privacy practices are governed by their own policies. If you connect Archilas to MCP clients, agent frameworks, or external APIs, you are responsible for ensuring you have appropriate rights and notices for data you send to Archilas.
16. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date and, where appropriate, notified by email or through the Service at least 30 days before they take effect. Continued use after the effective date constitutes acceptance of the updated Policy, except where prohibited by law.
17. Contact us
Questions or requests regarding this Privacy Policy:
hello@archilas.com
Archilas · Greece
See also our Terms of Service.